Methodology

How the ERM Maturity Index is scored

Published in full — the instrument, the mathematics, the framework mapping, and the limits of what the index can and cannot claim.

The instrument

The index is a structured self-assessment of eighteen questions across six domains — Governance & Culture, Risk Appetite, Risk Identification, Risk Assessment, Risk Treatment, and Monitoring & Reporting — with exactly three questions per domain, so no domain silently dominates the result. Each question offers five behaviorally anchored levels: concrete descriptions of practice, not agree/disagree statements. The respondent selects the description closest to their organization's current reality.

After the eighteen scored items, two unscored questions record which risk areas are formally present in the respondent's risk register, and what the risk report their leadership receives actually contains. Neither enters a score or a maturity statistic; both are reported only as coverage findings.

One definition diverges, and it is stated rather than buried. THIQL follows the National Risk Council glossary, under which tolerance limits are derived from risk appetite after treatment plans and controls are in place. COSO, the IRM and the HM Treasury Risk Appetite Guidance Note set tolerance before treatment — the boundary a treatment must bring the risk inside. The instrument follows the national definition; readers working to an international framework should read item 4 with that difference in mind.

Before the questions, respondents provide a short organization profile — industry, size, sector type, and country — so results are read in context. No identifying information is collected with the assessment itself.

Scoring

Each answer is scored 1–5 by its level. A domain score is the mean of its three questions, rescaled linearly to a 0–100 scale. The overall index is the unweighted mean of the six domain scores — every domain carries equal weight.

domain = (sum(answers) − 3) / 12 × 100
index  = mean(domain₁ … domain₆)
Index rangeMaturity level
0–19Initial — ad-hoc and person-dependent
20–39Developing — foundations without traction
40–59Defined — structured, not yet strategic
60–79Managed — embedded and decision-driving
80–100Optimized — a genuine competitive capability

Framework mapping

The index has three layers, and they do not share a source. The six-domain architecture maps to ISO 31000:2018 and COSO ERM 2017. The five-level ladder is risk-maturity modelling convention, closest to the RIMS Risk Maturity Model, and belongs to no ISO or COSO standard. The wording of every question was authored against the Saudi National Risk Council’s published corpus, the HM Treasury Orange Book (2023), and named technical standards where a definition was required. The full source list follows.

DomainISO 31000:2018COSO ERM 2017Authored against
Governance & Culture§5.2 Leadership and commitment · §5.4.3 roles, authorities and accountabilitiesGovernance & Culture (Principles 1–2, 4)National glossary terminology; the IIA Three Lines Model (2020) — management ownership, oversight, independent assurance; NCA ECC-1:2018 1-3-1 and CMA CG Regulations art. 21(1)(a) (policy approval)
Risk AppetiteRisk criteria (§6.3.4)Strategy & Objective-Setting (Principle 7)HM Treasury Risk Appetite Guidance Note v2.0 (UK Government Finance Function); Orange Book A5, D6, D14; national glossary (appetite, tolerance); RIMS Risk Maturity Model, attribute 3 (Risk Appetite Management)
Risk Identification§6.4.2 Risk identificationPerformance — identifies risk (Principle 10)National glossary (risk register); IEC 31010 Annex B.10.2 (register contents); Orange Book horizon scanning
Risk Assessment§6.4.3 Risk analysis · §6.4.4 Risk evaluationPerformance — assesses severity (Principle 11)IEC/ISO 31010 §5.3.1; NIST SP 800-30 Rev.1; CMA CG Regulations arts. 51–56
Risk Treatment§6.5 Risk treatmentPerformance — implements responses (Principle 13)National glossary (treatment options, risk owner, residual risk); Orange Book D7
Monitoring & Reporting§6.6 Monitoring and review · §6.7 Recording and reportingReview & Revision; Information, Communication & ReportingNational glossary (KRI definition); Orange Book D5, D13, D14
Two notes for precise readers. In ISO 31000, “risk assessment” is the whole of §6.4 — identification, analysis and evaluation together; the domain of that name here covers the analysis and evaluation steps. And two framework constructs are deliberately not scored by the 18 items: prioritization as a distinct discipline (COSO Principle 12), and independent evaluation of the risk framework itself (ISO §5.6; Principle 17).

The evidence base

Published in full, with the locator each source was used at. A claim that cannot be traced to one of these lines does not belong in the instrument.

Validity and sample thresholds

The index is a directional self-assessment of perceived maturity, and the strength of any aggregate claim depends on sample size. THIQL holds itself to the following thresholds before publishing:

ClaimMinimum sample
Directional aggregate findingsn ≥ 50
Mean scores at ±5 points (95% confidence)n ≈ 60–70
Internal reliability (Cronbach's α) & factor structuren = 100–200
Segment benchmarks (per industry / size band)n ≥ 30 per segment
A published national indexn ≥ 200 with sector spread

Data quality — the exclusion rule

Fixed before the first response was collected, and unchanged between publications. Every response records its completion time and whether its answers were straight-lined. A response is excluded from published statistics if it was completed in under two minutes and fifteen seconds, or if 14 or more of its 18 answers are identical — the same flag the instrument computes at submission. Excluded responses are retained but not counted, and every publication states the number excluded under this rule.

Limitations — stated plainly

The index is a single-respondent self-report: it measures perceived maturity from the respondent's vantage point, not an audited rating. Respondents are self-selected, so aggregates describe participating organizations, never a statistically representative national sample. Equal domain weighting is a deliberate, transparent default; empirically derived weights become possible once sufficient data exists. Anchored level descriptions reduce — but cannot eliminate — the optimism bias inherent in self-assessment.

Anonymous scores and organization profiles become part of THIQL's research dataset, which is published as findings and used to build THIQL's benchmarks, reports and research products. Contact details are collected only when a respondent requests something that requires them, are used for that purpose, and are not part of that dataset.

Take the ERM assessment →